Legal
Privacy Policy
What we collect, why we collect it, and the control you have over it. We keep it to the minimum.
Last updated:
Terms of ServiceOn this page
Who we are
This Privacy Policy explains how the team behind Lynx (“we”, “us”) handles your personal data. It applies to the Lynx website, the Lynx UI, dashboard and support channels.
We built Lynx to collect as little as possible. This policy explains what that is, why we need it and the control you have over it.
What we collect
Information you give us
- Email address. Used to sign you in to the dashboard and send you service messages.
- Account password. Used to sign you in to Lynx. We store it only as a salted hash, never in plain text, and cannot read it back.
- Support messages. What you send us on Discord, together with your Discord username.
Information created when you use Lynx
- License details. Your license key and its activation date.
- Hashed hardware ID. A one-way hash derived from your device’s hardware identifiers. We store the hash, not the identifiers themselves, and use it to bind your license to your device and in script requests, as described below.
- IP address and security logs. Your IP address, timestamps, Lynx UI version and the result of license checks, used to prevent fraud, key sharing and abuse.
- Approximate location. Each time your license is used, we record an approximate location (such as country, region and city) derived from your IP address. We do not use GPS or any precise location. It lets us spot a key being used from places far apart, a sign that it is being shared.
- HWID reset log. When you reset your HWID, we log the time, the reason you give, and whether the new hardware ID differs from the previous one, together with the approximate locations your license is used from before and after the reset. We use this to detect and prevent key sharing.
- Windows version. The version and build of Windows on your PC, used for compatibility and troubleshooting.
- Crash reports. When Lynx crashes, a report with technical details of the crash and your system, used to find and fix bugs.
Script HTTP requests
Scripts you run in Lynx can make HTTP requests to servers of their choosing. Lynx adds your hashed hardware ID to every such request in a header, so the receiving server can see it. Those servers are run by third parties, not by us, and their own privacy practices apply.
What we do not collect
Keys are bought from third-party resellers, which handle your payment under their own privacy policies. We do not receive your payment details or order information: the only part of your purchase we see is the license key you activate. We do not use advertising or cross-site tracking, and we do not sell personal data.
Why we use it
We use personal data only for the purposes below, each with a legal basis under the GDPR.
- Deliver your licenseContract
- Activating your key on your device and verifying it when Lynx starts.
- Prevent fraud and abuseLegitimate interests
- Detecting key sharing, resale, keys from reversed or fraudulent purchases and attacks on our infrastructure, including reviewing HWID resets and the approximate locations a license is used from.
- Fix crashes and bugsLegitimate interests
- Using crash reports and your Windows version to find, reproduce and fix problems in Lynx.
- SupportContract
- Answering your questions and resolving license or HWID issues.
- Service messagesContract
- Important notices about your license, security or changes to our policies. Never marketing without your consent.
Where we rely on legitimate interests, we have weighed them against your rights, and you can object at any time. See Your rights.
How long we keep it
- Email and license details
- For the life of your license, and up to 12 months after it ends.
- Hashed hardware ID
- For the life of your license. Replaced when you reset your HWID.
- Hashed password
- For the life of your account. Replaced when you change your password.
- IP address and security logs
- 90 days, unless needed longer to investigate a specific case of abuse.
- Approximate location
- 90 days, unless needed longer to investigate a specific case of abuse.
- HWID reset log
- For the life of your license, so repeated resets can be recognized.
- Windows version
- Kept indefinitely.
- Crash reports
- Deleted automatically after 6 months. We keep only the number of crashes.
- Support conversations
- 12 months after the conversation ends.
When data is no longer needed, we delete it or anonymize it.
Security
Data is encrypted in transit with TLS. Passwords are salted and hashed, never stored in plain text. Hardware identifiers are hashed before they are stored, access to personal data is limited to the people who need it, and our systems are monitored for abuse.
No system is perfectly secure. If a breach affects your personal data, we will notify you and the relevant authorities as the law requires.
Your rights
Depending on where you live, including under the EU and UK GDPR, you have the right to:
- Access a copy of the personal data we hold about you.
- Correct data that is inaccurate or incomplete.
- Delete your data.
- Restrict how we use your data.
- Port your data, in a structured, machine-readable format.
- Object to processing based on legitimate interests.
- Withdraw consent at any time, where we rely on it.
To make a request, contact us on Discord. We may ask you to confirm that you own the license key or email address involved. We respond within 30 days.
Deleting your data ends your license, because we cannot deliver or protect a license without it.
You also have the right to lodge a complaint with your local data protection authority.